Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

deskbar and some other stuff [RESOLVED]


  • This topic is locked This topic is locked

#1
WalrusGiraffe

WalrusGiraffe

    Member

  • Member
  • PipPip
  • 17 posts
Logfile of HijackThis v1.99.1
Scan saved at 4:08:12 PM, on 8/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\rundll.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\HSMIDI.EXE
C:\Program Files\AIM95\aim.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\system32\zqskw.exe
c:\kybrdff_13.exe
C:\WINDOWS\system32\n9nyb.exe
C:\WINDOWS\system32\ghynf.exe
c:\dfndrff_13.exe
C:\WINDOWS\system32\cvn0.exe
C:\WINDOWS\sys02327135032-1.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\PROGRA~1\COMMON~1\rruq\rruqm.exe
C:\PROGRA~1\COMMON~1\rruq\rruqa.exe
C:\WINDOWS\rdeirivA.exe
C:\Program Files\PSLister\PSLister.exe
c:\ac3_0003.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Batty2\Batty2.exe
c:\ucmoreiex.exe
C:\Program Files\CMFibula\CMFibula.exe
C:\WINDOWS\system32\czuehf.exe
C:\WINDOWS\system32\ha3f.exe
C:\WINDOWS\system32\fufudc.exe
c:\nwnmff_13.exe
C:\WINDOWS\explorer.exe
C:\Program Files\XoftSpySE\XoftSpy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\yeh\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalo.../search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalo.../search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\oycmw.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,aujqhdk.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SEARCHESSISTANT Helper - {4E7BD74F-2B8D-46A1-83B8-BD2AE6D9FA2E} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O3 - Toolbar: SEARCHESSISTANT Search - {4E7BD74F-2B8D-469F-83B8-BD2AE6D9FA2E} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL
O3 - Toolbar: SEARCHESSISTANT Related - {4E7BD74F-2B8D-469E-83B8-BD2AE6D9FA2E} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [System Files Updater] C:\WINDOWS\FlyakiteOSX\Tools\System Files Updater.exe /S
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [MIDI Sound Handler] HSMIDI.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [keyboard] c:\\kybrdff_13.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [defender] c:\\dfndrff_13.exe
O4 - HKLM\..\Run: [sys02327135032-1] C:\WINDOWS\sys02327135032-1.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [rdeirivA] C:\WINDOWS\rdeirivA.exe
O4 - HKLM\..\Run: [wqs8c187] RUNDLL32.EXE w0021562.dll,n 0038c184000000030021562
O4 - HKLM\..\Run: [RreN4HW] C:\WINDOWS\system32\czuehf.exe
O4 - HKLM\..\Run: [newname] c:\\nwnmff_13.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\RunOnce: [MIDI Sound Handler] HSMIDI.EXE
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...Bridge-c106.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay10...es/MsnPUpld.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.web...otoUploader.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - AppInit_DLLs: repairs303169590.dll
O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\ldrmonui.dll
O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\mrvcrt40.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\ndrssk.dll
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\tkrmmgr.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: cmdService - Unknown owner - C:\WINDOWS\WUVIIFhQ\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: rundll.exe - Unknown owner - C:\WINDOWS\rundll.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\rdeiriv.exe

*end log*

i tried disabling system restore and running adaware and xoftspy in safe mode. deleted the files and registry keys/values that i could and what seemed to be the problematic files and folders. everything i delete gets recreated when i restart my computer.
  • 0

Advertisements


#2
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Welcome to geekstogo. I'm Ryan, and I'll be helping you clean up your computer.

1. Download Ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded Ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete, run Ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close Ewido anti-spyware, Do Not run a scan just yet

2. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Do not do anything with these yet!

4. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.

5. IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your desktop (This is important)
  • Close Ewido and reboot your system back into Normal Mode.
6. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon Posted Image and select alcanshorty.bfu
  • Press Execute and let it do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Reboot into normal windows and post the contents of Ewido text report that you saved and a new HiJackThis log.
  • 0

#3
WalrusGiraffe

WalrusGiraffe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
my ewido stops responding when it reaches adware.surfside or something of the sort during the "apply all actions" part of what you told me to do. Tried twice and both times ewido crashed. Should i just skip that and go on to save the report or is there something else i should do?
  • 0

#4
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Post a new HiJack This log and we'll go from there.

-Ryan
  • 0

#5
WalrusGiraffe

WalrusGiraffe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Logfile of HijackThis v1.99.1
Scan saved at 9:15:17 PM, on 8/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\WUVIIFhQ\command.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\rundll.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\WINDOWS\FlyakiteOSX\Tools\System Files Updater.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\HSMIDI.EXE
C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\System32\svchost.exe
C:\kybrdff_13.exe
C:\WINDOWS\rdeirivA.exe
C:\WINDOWS\system32\zqskw.exe
C:\WINDOWS\system32\n9nyb.exe
C:\WINDOWS\Duce6.exe
C:\nwnmff_13.exe
C:\WINDOWS\system32\ghynf.exe
C:\WINDOWS\win320932-13271350.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\FlyakiteOSX\Tools\ResHacker.exe
C:\Program Files\AIM95\aim.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Documents and Settings\yeh\Desktop\HijackThis.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\cvn0.exe
c:\dfndrff_13.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.fin...siteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.fin...siteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalo.../search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalo.../search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\oycmw.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,aujqhdk.exe
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {162FEC98-862B-4252-AC39-FF06496EBAC4} - C:\Program Files\NetMeeting\horef.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [System Files Updater] C:\WINDOWS\FlyakiteOSX\Tools\System Files Updater.exe /S
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [MIDI Sound Handler] HSMIDI.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_13.exe
O4 - HKLM\..\Run: [rdeirivA] C:\WINDOWS\rdeirivA.exe
O4 - HKLM\..\Run: [lpu8cb3c] RUNDLL32.EXE w001df3f.dll,n 0038cb3900000003001df3f
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_13.exe
O4 - HKLM\..\Run: [win320932-13271350] C:\WINDOWS\win320932-13271350.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [defender] c:\\dfndrff_13.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...Bridge-c106.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay10...es/MsnPUpld.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.web...otoUploader.CAB
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn....FreeInstall.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - AppInit_DLLs: repairs303169590.dll,wbsys.dll
O20 - Winlogon Notify: App Paths - C:\WINDOWS\system32\kndbene.dll
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32\fqlemgmt.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\WUVIIFhQ\command.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: rundll.exe - Unknown owner - C:\WINDOWS\rundll.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\rdeiriv.exe (file missing)
  • 0

#6
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
I would like to see an Uninstall list.

Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)

-Ryan
  • 0

#7
WalrusGiraffe

WalrusGiraffe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 6.0.1
Adobe Stock Photos 1.0
Advanced WMA Workshop version 2.1
AOL Instant Messenger (SM)
ATI Display Driver
Azureus
BitTorrent 4.0.3
Bonjour Core for Windows
BroadJump Client Foundation
[email protected] Automatic Updates Policy
CloneCD
CloneDVD2
Command
Creative PC-CAM Center
Creative WebCam Monitor
Creative WebCam Notebook Driver (1.04.01.0322)
Creative WebCam Notebook User's Guide (English)
CursorXP
CuteFTP 7 Professional
DC++ 0.674
DeadAIM
DivX
DivX Player
DVD Decrypter (Remove Only)
ewido anti-spyware 4.0
FlyakiteOSX
Forethought
Google Earth
Google Toolbar for Internet Explorer
GUILTY GEAR XX #RELOAD
Haali Media Splitter
HijackThis 1.99.1
HLSW v1.0.0.47
Internet Optimizer
IsoBuster 1.7
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 8
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player 8
Macromedia Shockwave Player
Matroska Pack
Microsoft Office XP Professional with FrontPage
middle_man
mIRC
Mozilla Firefox (1.5.0.5)
MSN Music Assistant
Nero OEM
Network Monitor
NVIDIA Drivers
oggcodecs 0.71.0946
PowerDVD
Quicklinks
QuickTime
RealPlayer Basic
Realtek AC'97 Audio
SBC Self Support Tool
Search Bar
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
SmartFTP Client
Starcraft
Steam
StuffPlug-NG (Messenger Plus! Plugins)
Surf SideKick
TargetSaver
UCmore - The Search Accelerator
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
USB Dual Vibration Joystick
VideoLAN VLC media player 0.8.5
Web Nexus Network
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Media Format Runtime
Windows Media Player 10
Windows Overlay Components
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
XoftSpySE
Yahoo! Widget Engine
Yahoo! Widget Engine
  • 0

#8
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
You will want to print out a copy of these instructions to follow while you complete this procedure, as you will not be able to access the internet later in the fix.


Please go to Add/Remove Programs in the Control Panel and remove the following programs (if listed):

Azureus
BitTorrent 4.0.3 <=This and Azureus are on this list due to the complicated legal position regarding Peer-to-peer clients. While I recommend that you remove them, the final choice is up to you. Please be aware that they can also bring you infected files, putting your computer at greater risk.

Command
Internet Optimizer
Quicklinks
Search Bar
Surf SideKick
TargetSaver


Open HiJack This and scan. When it finishes, put an X in the box next to these following item(s)


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.fin...siteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.fin...siteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\oycmw.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,aujqhdk.exe
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing)
O2 - BHO: (no name) - {162FEC98-862B-4252-AC39-FF06496EBAC4} - C:\Program Files\NetMeeting\horef.dll (file missing)
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_13.exe
O4 - HKLM\..\Run: [rdeirivA] C:\WINDOWS\rdeirivA.exe
O4 - HKLM\..\Run: [lpu8cb3c] RUNDLL32.EXE w001df3f.dll,n 0038cb3900000003001df3f
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_13.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [defender] c:\\dfndrff_13.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...Bridge-c106.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn....FreeInstall.cab
O20 - AppInit_DLLs: repairs303169590.dll,wbsys.dll
O20 - Winlogon Notify: App Paths - C:\WINDOWS\system32\kndbene.dll
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32\fqlemgmt.dll



Close all open windows except for HiJack This and click fix checked.




Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\Duce6.exe
    C:\Program Files\SurfSideKick 3\
    C:\WINDOWS\system32\oycmw.exe
    C:\WINDOWS\nem220.dll
    C:\Program Files\NetMeeting\horef.dll
    C:\Program Files\Deskbar\deskbar.dll
    C:\WINDOWS\system32\xeymi.dll
    C:\WINDOWS\system32\wfxqhv.exe
    C:\WINDOWS\system32\cvn0.exe
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\system32\kndbene.dll
    C:\WINDOWS\system32\fqlemgmt.dll
    C:\WINDOWS\rundll.exe
    C:\WINDOWS\rdeiriv.exe


  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


After the reboot, rescan with HijackThis and post a fresh log in this same topic, and let us know how your system's working. :whistling:

-Ryan
  • 0

#9
WalrusGiraffe

WalrusGiraffe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Logfile of HijackThis v1.99.1
Scan saved at 1:34:25 AM, on 8/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HSMIDI.EXE
C:\WINDOWS\win320932-13271350.exe
C:\WINDOWS\rdeirivA.exe
C:\Program Files\AIM95\aim.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\yeh\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\oycmw.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,aujqhdk.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [MIDI Sound Handler] HSMIDI.EXE
O4 - HKLM\..\Run: [win320932-13271350] C:\WINDOWS\win320932-13271350.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [rdeirivA] C:\WINDOWS\rdeirivA.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [rruq] C:\PROGRA~1\COMMON~1\rruq\rruqm.exe
O4 - HKCU\..\RunOnce: [MIDI Sound Handler] HSMIDI.EXE
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: rundll.exe - Unknown owner - C:\WINDOWS\rundll.exe (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\rdeiriv.exe (file missing)

*end log*

the internet optimizer wont die and the F2's from the hijackthis log wont die either. im also still getting popups every few minutes...and i still cant keep regedit and task manager open for more than a second or two. the deskbar is gone though.

Edited by WalrusGiraffe, 26 August 2006 - 02:59 AM.

  • 0

#10
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Open ewido anit-malware
  • On the main screen select the icon "Update" then select the "Update now" link.
  • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the results of the ewido report scan as well as a new HiJack This log.
-Ryan
  • 0

Advertisements


#11
WalrusGiraffe

WalrusGiraffe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
my ewido log has like...nearly 400 lines describing quarantines. dont know if you really wanna go through all that crap. but heres the new hijickthis log:

Logfile of HijackThis v1.99.1
Scan saved at 9:54:17 PM, on 8/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HSMIDI.EXE
C:\WINDOWS\rdeirivA.exe
C:\WINDOWS\Duce6.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\ms047135032-132.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\yeh\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\oycmw.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,aujqhdk.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [MIDI Sound Handler] HSMIDI.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [rdeirivA] C:\WINDOWS\rdeirivA.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [ms047135032-132] C:\WINDOWS\ms047135032-132.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [rruq] C:\PROGRA~1\COMMON~1\rruq\rruqm.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [MIDI Sound Handler] HSMIDI.EXE
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: rundll.exe - Unknown owner - C:\WINDOWS\rundll.exe (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\rdeiriv.exe (file missing)
  • 0

#12
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Yes, please post the log from ewido (may take two replies)

-Ryan
  • 0

#13
WalrusGiraffe

WalrusGiraffe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:05:35 PM 8/26/2006

+ Scan result:



C:\Program Files\Batty2\Batty2.dll -> Adware.CASClient : Cleaned with backup (quarantined).
C:\Program Files\Batty2\Batty2.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\Program Files\CMFibula\CMFibula.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\WINDOWS\WUVIIFhQ\asappsrv.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\WINDOWS\WUVIIFhQ\command.exe -> Adware.CommAd : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
C:\Program Files\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\Program Files\Internet Optimizer\optimize.exe -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-1214440339-73586283-839522115-1003\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\!KillBox\fqlemgmt.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W50NGTMV\Installer[2].exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temp\temp.fr83BA -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temp\temp.frF982 -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temp\shopbiz.exe -> Adware.MDH : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\29ABCVW9\shopbiz[1].exe -> Adware.MDH : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\shopbiz.exe -> Adware.MDH : Error during cleaning.
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj.1 -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CLSID -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CurVer -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-21-1214440339-73586283-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\PSLister\PSLister.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S1KLMLAB\bbqa[1].cab/cvn0.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\A5AC.tmp/cvn0.exe -> Adware.SearchAssistant : Error during cleaning.
C:\WINDOWS\Temp\D5D1.tmp/cvn0.exe -> Adware.SearchAssistant : Error during cleaning.
C:\WINDOWS\Temp\E7A33.tmp/cvn0.exe -> Adware.SearchAssistant : Error during cleaning.
C:\WINDOWS\Temp\F3A1.tmp/cvn0.exe -> Adware.SearchAssistant : Error during cleaning.
C:\WINDOWS\system32\bez6n4r21.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\WINDOWS\system32\fufudc.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ghynf.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\WINDOWS\system32bez6n4r21.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\WINDOWS\system32fufudc.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\WINDOWS\system32ghynf.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\!KillBox\deskbar.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\!KillBox\wfxqhv.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S1KLMLAB\bbqa[1].cab/wfxqhv.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S1KLMLAB\bbqa[1].cab/zqskw.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\A5AC.tmp/wfxqhv.exe -> Adware.Suggestor : Error during cleaning.
C:\WINDOWS\Temp\A5AC.tmp/zqskw.exe -> Adware.Suggestor : Error during cleaning.
C:\WINDOWS\Temp\D5D1.tmp/wfxqhv.exe -> Adware.Suggestor : Error during cleaning.
C:\WINDOWS\Temp\D5D1.tmp/zqskw.exe -> Adware.Suggestor : Error during cleaning.
C:\WINDOWS\Temp\E7A33.tmp/wfxqhv.exe -> Adware.Suggestor : Error during cleaning.
C:\WINDOWS\Temp\E7A33.tmp/zqskw.exe -> Adware.Suggestor : Error during cleaning.
C:\WINDOWS\Temp\F3A1.tmp/wfxqhv.exe -> Adware.Suggestor : Error during cleaning.
C:\WINDOWS\Temp\F3A1.tmp/zqskw.exe -> Adware.Suggestor : Error during cleaning.
C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kcnzrop6.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\n9nyb.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\zqskw.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32n9nyb.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temp\da7C.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temp\i72.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\da41.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\i1C.tmp -> Adware.SurfSide : Error during cleaning.
C:\WINDOWS\Temp\i3C.tmp -> Adware.SurfSide : Error during cleaning.
C:\WINDOWS\Temp\iD.tmp -> Adware.SurfSide : Error during cleaning.
C:\WINDOWS\Temp\iE.tmp -> Adware.SurfSide : Error during cleaning.
HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-21-1214440339-73586283-839522115-1003\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-21-1214440339-73586283-839522115-1003\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S1KLMLAB\ucmoreiex[1].exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S1KLMLAB\ucmoreiex[1].exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S1KLMLAB\ucmoreiex[1].exe/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\GLB1F.tmp/empty_00000001 -> Adware.Ucmore : Error during cleaning.
C:\WINDOWS\Temp\GLB20.tmp/empty_00000001 -> Adware.Ucmore : Error during cleaning.
C:\WINDOWS\Temp\GLB26.tmp/empty_00000001 -> Adware.Ucmore : Error during cleaning.
C:\WINDOWS\Temp\GLB4B.tmp/empty_00000001 -> Adware.Ucmore : Error during cleaning.
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\MediaAccX.Installer -> Adware.WinAd : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\MediaAccX.Installer\CLSID -> Adware.WinAd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0P0V0HGL\nwnmff_13[1].exe -> Downloader.Adload.cy : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S1KLMLAB\loader[1].exe -> Downloader.Adload.eo : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0P0V0HGL\drsmartload292a[1].exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S1KLMLAB\drsmartload45a[1].exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W50NGTMV\drsmartload46a[1].exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W50NGTMV\drsmartload849a[1].exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\!KillBox\dmonwv.dll -> Downloader.Agent.agw : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\Y5IJQFSH\fym9bvo[1].exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\CPKLY5C1\installerwnus[1].exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temp\tp7543.exe -> Downloader.Qoologic.ax : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\Y5IJQFSH\rcverlib[1].exe -> Downloader.Qoologic.ax : Cleaned with backup (quarantined).
C:\!KillBox\( 1) -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temp\f10013218.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temp\f192859.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\f104453.exe -> Downloader.Qoologic.bj : Error during cleaning.
C:\WINDOWS\Temp\f118187.exe -> Downloader.Qoologic.bj : Error during cleaning.
C:\WINDOWS\Temp\f2822921.exe -> Downloader.Qoologic.bj : Error during cleaning.
C:\WINDOWS\system32\enalj.dat -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[732] C:\WINDOWS\system32\fwkiogv.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\4Z6RYZ65\al3[1].txt -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w099041e.dll -> Downloader.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\EROHAP81\MTE3NDI6ODoxNg[1].exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\4Z6RYZ65\MTE3NDI6ODoxNg[1].exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\29ABCVW9\ac3_0003[1].exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\29ABCVW9\stub_113_4_0_4_0[1].exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0P0V0HGL\kybrdff_13[1].exe -> Downloader.VB.alg : Cleaned with backup (quarantined).
C:\WINDOWS\offun.exe -> Downloader.VB.nw : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\29ABCVW9\803_104[1].exe -> Dropper.Mudrop.bq : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\4Z6RYZ65\SS1001[1].exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\CPKLY5C1\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\Y5IJQFSH\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\!KillBox\rdeiriv.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\Documents and Settings\yeh\Local Settings\Temporary Internet Files\Content.IE5\Y5IJQFSH\dfndrff_13[1].exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla\Firefox\Profiles\o3cunnqh.default\Cache\B23E4567d01 -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
:mozilla.758:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.197:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.198:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.199:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.200:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.201:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.202:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.203:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.204:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.205:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.206:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.207:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.208:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.209:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.210:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.211:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.212:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.213:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.214:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.215:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.216:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.217:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.524:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.532:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.721:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.752:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.301:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.304:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.307:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.378:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.763:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.878:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.879:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.557:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.558:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.559:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.560:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.845:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.846:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.847:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.848:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.849:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.843:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.844:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Adtrak : Cleaned.
:mozilla.56:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.57:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.58:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.59:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.61:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.62:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.12:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.528:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.447:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.778:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.779:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.457:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.458:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.459:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.460:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.461:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.462:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.338:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.276:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.277:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.278:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.279:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.144:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.

Edited by WalrusGiraffe, 27 August 2006 - 01:23 PM.

  • 0

#14
WalrusGiraffe

WalrusGiraffe

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.35:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.247:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.529:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.530:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.531:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.347:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.348:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.349:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.350:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.351:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.352:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.353:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.386:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.387:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.388:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.389:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.390:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.889:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.890:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.438:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.439:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.229:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.230:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.231:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.232:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.233:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.491:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.502:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.503:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.680:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.681:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.699:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.821:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.822:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.823:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.851:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.385:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Kmpads : Cleaned.
:mozilla.396:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned.
:mozilla.397:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.488:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.489:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.490:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.695:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.698:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.816:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.817:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.135:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.136:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.318:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.319:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.320:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.331:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.332:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.704:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.20:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.31:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.32:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.33:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.34:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.587:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Popularix : Cleaned.
:mozilla.506:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.910:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.911:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.63:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.64:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.65:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Realcastmedia : Cleaned.
:mozilla.10:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\o3cunnqh.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.262:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.263:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.264:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.265:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.266:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.6:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\o3cunnqh.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.7:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\o3cunnqh.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.8:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\o3cunnqh.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.9:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\o3cunnqh.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.686:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.181:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.182:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.183:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.184:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.185:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.186:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.187:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.188:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.189:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.190:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Searchingbooth : Cleaned.
:mozilla.267:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.268:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.269:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.270:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.409:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.410:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.411:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.412:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.413:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.414:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.174:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.175:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.176:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.177:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.178:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.366:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.367:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.368:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.369:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned.
:mozilla.280:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.281:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.282:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.283:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.284:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.285:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.286:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.287:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.288:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.289:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.290:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.291:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.292:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.293:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.294:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.295:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.296:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.297:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.298:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.114:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.116:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.122:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.123:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.124:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.633:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.485:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.486:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt -> TrackingCookie.Top-banners : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Top-banners : Cleaned.
:mozilla.538:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.339:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.340:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.341:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.342:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.343:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.344:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.345:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.346:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.259:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.260:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.509:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.689:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.690:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.161:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.162:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.163:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.164:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.165:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.166:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.167:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.168:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.169:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.170:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.171:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.125:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.126:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.127:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.128:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.129:C:\Documents and Settings\yeh\Application Data\Mozilla\Firefox\Profiles\nhakjsvv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\yeh\Cookies\[email protected][1].txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\unwn.exe -> Trojan.Qoologic : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ha3f.exe -> Trojan.Runner.j : Cleaned with backup (quarantined).
C:\WINDOWS\system32ha3f.exe -> Trojan.Runner.j : Cleaned with backup (quarantined).
C:\WINDOWS\sys02327135032-1.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\WINDOWS\uni_ehhhh.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\WINDOWS\uninst104.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\WINDOWS\win320932-13271350.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\WINDOWS\win32102-1327135032006.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).


::Report end

Edited by WalrusGiraffe, 27 August 2006 - 01:24 PM.

  • 0

#15
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
OK, looks like ewido took care of almost everything, we should be able to finish soon.

You will want to print out a copy of these instructions to follow while you complete this procedure, as you will not be able to access the internet later in the fix.

Please open notepad, and copy and paste everything in the code box below into it.

sc stop "Network Monitor"
sc delete "Network Monitor"
sc stop rundll.exe
sc delete rundll.exe
sc stop "Windows Overlay Components"
sc delete "Windows Overlay Components"
taskkill /im ms047135032-132.exe /f
del "C:\WINDOWS\ms047135032-132.exe"
taskkill /im Duce6.exe /f
del "C:\WINDOWS\Duce6.exe"
taskkill /im rdeirivA.exe /f
del "C:\WINDOWS\rdeirivA.exe"
taskkill /im netmon.exe /f
del "C:\Program Files\Network Monitor\netmon.exe"
taskkill /im rdeiriv.exe /f
del "C:\WINDOWS\rdeiriv.exe"
taskkill /im oycmw.exe /f
del "C:\WINDOWS\system32\oycmw.exe"

Save the file as "begone.bat" (include the quotes) to your desktop. It should look like a white DOS window with a gear inside.


Please reboot into safe mode (continually tap the F8 key while your system is starting, select Safe Mode from the menu).

Double click on begone.bat. A black window will open, and then quickly close, this is normal.


Open HiJack This and scan. When it finishes, put an X in the box next to these following item(s)


R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\oycmw.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,aujqhdk.exe
O4 - HKLM\..\Run: [rdeirivA] C:\WINDOWS\rdeirivA.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [ms047135032-132] C:\WINDOWS\ms047135032-132.exe
O4 - HKCU\..\Run: [rruq] C:\PROGRA~1\COMMON~1\rruq\rruqm.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: rundll.exe - Unknown owner - C:\WINDOWS\rundll.exe (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\rdeiriv.exe (file missing)



Close all open windows except for HiJack This and click fix checked.

Reboot your PC.

If you would please, rescan with HijackThis and post a fresh log in this same topic, and let us know how your system's working. :whistling:

-Ryan

Edited by rmurphy, 27 August 2006 - 05:42 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP